Path: utzoo!utgpu!news-server.csri.toronto.edu!rpi!usc!cs.utexas.edu!uunet!iczer-1!emm From: emm@iczer-1.UUCP (Edward M. Markowski) Newsgroups: comp.sys.3b1 Subject: Re: COPS security audit and the unix pc. Message-ID: <580@iczer-1.UUCP> Date: 6 Apr 91 01:10:02 GMT References: <1991Mar23.004007.2024@shibaya.lonestar.org> <1991Mar26.225255.6048@ferret.ocunix.on.ca> <563@iczer-1.UUCP> <1991Apr03.201214.8915@ferret.ocunix.on.ca> Reply-To: emm@iczer-1.UUCP (Edward M. Markowski) Organization: The Kurowulf Empire Lines: 22 In article <1991Apr03.201214.8915@ferret.ocunix.on.ca> clewis@ferret.ocunix.on.ca (Chris Lewis) writes: |In article <563@iczer-1.UUCP> emm@iczer-1.UUCP (Edward M. Markowski) writes: |It's in the defs.h for B news. However, it won't work on System V systems |because of the way setuid/setgid programs, setuid()/setgid() and mkdir |works. (as in, if a setuid program calls mkdir, the directory ends up |being owned by the real user not the effective, rnews can't write |into it, and there's no "elegant" way around it in System V) Which is why |C-news goes to all of the kludgey junk for the "setnewsids" program which |runs as setuid root to run relaynews properly. | |Bnews has no such kludge, though you could retrofit setnewsids if you wanted. It works here. I am have a 3B1, which is running System V I do not seem to have that problem. -- ------------------------------------------------------------------------------- Edward M. Markowski -- iczer-1 Administrator ...the garage is flooded from the sprinkler. VOICE : (201) 478-6052 It also left a man's decapitated body, lying UUCP : ..!uunet!iczer-1!emm on the floor next to his own severed head. -or- : ..!tronsbox!iczer-1!emm A head which at this time has no name.